Search

Found 10,563 results in 924ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-3567 medium 5.5 FIX rhel sles rocky 1y ago A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This…
CVE-2023-6693 medium 5.5 FIX rhel rocky sles 1y ago A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_V…
CVE-2025-4093 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:4797: thunderbird security update (Important)
CVE-2025-4091 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…
CVE-2025-4087 high 8.0 FIX rhel rockydebian debian 1y ago A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and…
CVE-2025-4083 high 8.0 FIX rhel rockydebian debian 1y ago A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended f…
CVE-2025-2817 high 8.0 FIX rhel rockydebian debian 1y ago Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged…
CVE-2023-53064 high 8.0 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: iavf: fix hang on reboot with ice When a system with E810 with existing VFs gets rebooted the following hang may be observed. P…
CVE-2025-21927 high 8.0 FIX rhel sles rocky 1y ago Important: kernel security update
CVE-2024-46826 medium 5.5 FIX rhel rocky sles 1y ago In the Linux kernel, the following vulnerability has been resolved: ELF: fix kernel.randomize_va_space double read ELF loader uses "randomize_va_space" twice. It is sysctl and can change at any mom…
CVE-2024-44990 medium 5.5 5.5 FIX rhel rocky sles 1y ago In the Linux kernel, the following vulnerability has been resolved: bonding: fix null pointer deref in bond_ipsec_offload_ok We must check if there is an active slave before dereferencing the point…
CVE-2024-42322 high 8.0 FIX rhel rocky sles 1y ago In the Linux kernel, the following vulnerability has been resolved: ipvs: properly dereference pe in ip_vs_add_service Use pe directly to resolve sparse warning: net/netfilter/ipvs/ip_vs_ctl.c:1…
CVE-2024-42292 high 7.1 7.1 FIX rhel rocky sles 1y ago In the Linux kernel, the following vulnerability has been resolved: kobject_uevent: Fix OOB access within zap_modalias_env() zap_modalias_env() wrongly calculates size of memory block to move, so w…
CVE-2020-27792 medium 5.5 FIX rocky slesdebian debian 1y ago RHSA-2025:4362: ghostscript security update (Moderate)
CVE-2025-3523 high 8.0 FIX rhel sles rocky 1y ago RHSA-2025:4649: thunderbird security update (Important)
CVE-2025-3522 high 8.0 FIX rhel sles rocky 1y ago RHSA-2025:4649: thunderbird security update (Important)
CVE-2025-2830 high 8.0 FIX rhel sles rocky 1y ago RHSA-2025:4649: thunderbird security update (Important)
CVE-2025-1861 medium 5.5 FIX rockyalmalinux almalinux rhel 1y ago Moderate: php:8.1 security update
CVE-2025-1736 medium 5.5 FIX rockyalmalinux almalinux rhel 1y ago Moderate: php:8.1 security update
CVE-2025-1734 medium 5.5 FIX rockyalmalinux almalinux rhel 1y ago Moderate: php:8.1 security update
CVE-2025-1219 medium 5.5 FIX rocky rhelalmalinux almalinux 1y ago Moderate: php:8.1 security update
CVE-2025-1217 medium 5.5 FIX rockyalmalinux almalinux rhel 1y ago Moderate: php:8.1 security update
CVE-2025-0395 medium 6.2 6.2 FIX rhel rockydebian debian 1y ago RHSA-2025:3828: glibc security update (Moderate)
CVE-2024-8929 medium 5.5 FIX rocky rhelalmalinux almalinux 1y ago Moderate: php:8.1 security update
CVE-2024-11234 medium 5.5 FIX rocky rhel sles 1y ago Moderate: php:8.1 security update
CVE-2024-11233 medium 5.5 FIX rocky rhel sles 1y ago Moderate: php:8.1 security update
CVE-2024-55549 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:3615: libxslt security update (Important)
CVE-2025-30698 medium 5.5 FIX almalinux almalinux rhel rocky 1y ago Moderate: java-1.8.0-openjdk security update
CVE-2025-30691 medium 5.5 FIX rhel rocky sles 1y ago Moderate: java-1.8.0-openjdk security update
CVE-2025-21587 medium 5.5 FIX rhel rocky sles 1y ago Moderate: java-1.8.0-openjdk security update
CVE-2024-53150 medium 7.0 KEVFIX rhel rocky sles 1y ago Moderate: kernel security update
CVE-2025-22866 high 8.0 FIX rheldebian debian sles google 1y ago Important: delve and golang security update
CVE-2024-45341 medium 5.5 FIX rhel rockydebian debian 1y ago RHSA-2025:3772: go-toolset:rhel8 security update (Moderate)
CVE-2025-30427 high 8.0 FIX rhel rocky sles 1y ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS…
CVE-2025-24216 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processi…
CVE-2025-24209 high 8.0 FIX rhel rocky sles 1y ago A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processi…
CVE-2025-24208 high 8.0 FIX rhel rocky sles 1y ago A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
CVE-2025-24189 high 8.0 FIX rhel slesdebian debian 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted w…
CVE-2024-54551 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing web content m…
CVE-2024-54467 high 8.0 FIX rhel rocky sles 1y ago A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website …
CVE-2024-44192 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may…
CVE-2025-24813 medium 8.0 KEVEXPFIX rhel rocky sles 1y ago Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
CVE-2025-3030 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…
CVE-2025-3029 high 8.0 FIX rhel rockydebian debian 1y ago A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability was fixed in Firefox 137, Firefox ESR …
CVE-2025-3028 high 8.0 FIX rhel rockydebian debian 1y ago JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firefox ESR 115.22, Firefox ESR 128.9, Thunde…
CVE-2024-8176 medium 5.5 FIX rhel rockydebian debian 1y ago RHSA-2025:4048: xmlrpc-c security update (Moderate)
CVE-2024-43855 medium 5.5 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: md: fix deadlock between mddev_suspend and flush bio Deadlock occurs when mddev is being suspended while some flush bio is in pro…
CVE-2025-27363 high 9.5 KEVFIX rhel rockyarch arch 1y ago FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.
CVE-2025-1080 high 8.0 FIX rhel rocky sles 1y ago LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In th…
CVE-2023-53012 high 8.0 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: thermal: core: call put_device() only after device_register() fails put_device() shouldn't be called before a prior call to devic…
CVE-2025-30204 high 8.0 FIX rheldebian debian sles 1y ago RHSA-2025:7967: osbuild-composer security update (Important)
CVE-2025-29786 high 8.0 rheldebian debian sles 1y ago Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire strin…
CVE-2025-22869 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:3210: container-tools:rhel8 security update (Important)
CVE-2025-22868 high 8.0 FIX rheldebian debian sles 1y ago An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
CVE-2024-45336 medium 5.5 FIX rhel rockydebian debian 1y ago RHSA-2025:3772: go-toolset:rhel8 security update (Moderate)
CVE-2025-21785 high 8.0 FIX rhel rocky sles 1y ago In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bo…
CVE-2024-7347 medium 5.5 FIX rhel sles rocky 1y ago Moderate: nginx:1.24 security update
CVE-2025-27516 high 8.0 FIX rhel rockydebian debian 1y ago RHSA-2025:3388: python-jinja2 security update (Important)
CVE-2025-24855 high 8.0 FIX rhel rocky sles 1y ago RHSA-2025:3615: libxslt security update (Important)
CVE-2024-36293 high 8.0 FIX rocky slesdebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-31068 high 8.0 FIX rocky slesdebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-29214 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-28127 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-24582 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2024-10306 medium 5.5 rhel rocky 1y ago Moderate: mod_proxy_cluster security update
CVE-2023-43758 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2023-34440 high 8.0 FIX rocky rheldebian debian 1y ago RHEA-2025:3114: microcode_ctl bug fix and enhancement update (Important)
CVE-2025-24201 high 9.5 KEVFIX rhel rockydebian debian 1y ago Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vuln…
CVE-2025-0624 high 8.0 FIX rheldebian debian sles 1y ago Important: grub2 security update
CVE-2025-24928 high 8.0 FIX rhel rocky sles 1y ago libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted …
CVE-2024-56171 high 8.0 FIX rhel rocky sles 1y ago libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be va…
CVE-2025-24070 high 8.0 rhel rocky 1y ago RHSA-2025:2670: .NET 8.0 security, bug fix, and enhancement update (Important)
CVE-2024-53197 high 9.5 KEVFIX rhel rocky sles 1y ago Important: kernel security update
CVE-2024-53113 high 8.0 FIX rhel slesdebian debian 1y ago Important: kernel security update
CVE-2024-50302 medium 5.5 7.0 KEVFIX rhel rocky sles 1y ago Important: kernel security update
CVE-2024-50264 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2023-52922 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2023-52605 high 8.0 FIX rhel rocky sles 1y ago Important: kernel security update
CVE-2025-26601 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26600 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26599 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26598 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26597 high 7.8 7.8 FIX rhel rocky sles tigervncx.org 1y ago Important: tigervnc security update
CVE-2025-26596 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26595 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2025-26594 high 8.0 FIX rhel rocky sles 1y ago Important: tigervnc security update
CVE-2024-57807 high 8.0 FIX rocky slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Fix for a potential deadlock This fixes a 'possible circular locking dependency detected' warning CPU0 …
CVE-2025-1938 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…
CVE-2025-1937 high 8.0 FIX rhel rockydebian debian 1y ago Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that w…
CVE-2025-1936 high 8.0 FIX rhel rockydebian debian 1y ago jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was u…
CVE-2025-1935 high 8.0 FIX rhel rockydebian debian 1y ago A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird…
CVE-2025-1934 high 8.0 FIX rhel rockydebian debian 1y ago It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability was f…
CVE-2025-1933 high 8.0 FIX rhel rockydebian debian 1y ago On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fix…
CVE-2025-1932 high 8.0 FIX rhel rockydebian debian 1y ago An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, …
CVE-2025-1931 high 8.0 FIX rhel rockydebian debian 1y ago It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 136, Firefox ES…
CVE-2025-1930 high 8.0 FIX rhel rockydebian debian 1y ago On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability w…
CVE-2025-24162 high 8.0 FIX rhel rocky sles 1y ago This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing malicio…
CVE-2025-24150 high 8.0 FIX rocky slesdebian debian 1y ago A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command i…
CVE-2025-24143 high 8.0 FIX rocky slesdebian debian 1y ago The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, visionOS 2.3. A maliciously crafted web…
CVE-2024-54543 high 8.0 FIX rhel rocky sles 1y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processi…